Junglewise Threat Intelligence

CVE-2026-82243: Budibase Server SSRF in datasource verify endpoint

CVE-2026-82243 · Severity: high · CVSS 7.6 · Published 2026-08-28

Technologies: Budibase Server. Vendors: Budibase.

Executive brief

Budibase Server is a low-code application development platform used to build internal business applications. A vulnerability in the datasource verification endpoint allows builder-level users to send requests to arbitrary URLs without restriction. Attackers can exploit this to steal internal database credentials and gain unauthorized access to the entire application database in cloud deployments, potentially exposing all customer and operational data.

Technical details

The vulnerability is a Server-Side Request Forgery (SSRF) with credential leakage in the POST /api/datasources/verify endpoint (CWE-918). The CouchDB and Elasticsearch connectors fail to validate URLs supplied by builder-level users before making outbound HTTP requests. Critically, the CouchDB connector automatically attaches internal database credentials (COUCH_DB_USERNAME and COUCH_DB_PASSWORD) as Basic Authorization headers when connecting to the attacker-supplied URL. An authenticated builder-level user can trigger the vulnerability by submitting a malicious datasource configuration pointing to an attacker-controlled server, causing the application to leak encoded credentials and probe internal network services. The issue affects multiple endpoints (/datasources/verify, /datasources/info, /datasources/views, /datasources/relationships) and impacts both CouchDB (with credential leakage) and Elasticsearch (SSRF only) connectors. The fix, available in version 3.41.3, applies SSRF blacklist validation to all HTTP-based connectors before connection attempts.

Affected products

  • Budibase Server before 3.41.3

Timeline

  • 2026-08-14: advisory: GitHub Security Advisory GHSA-83m5-fvmg-r7xv published
  • 2026-08-28: disclosed: CVE-2026-82243 disclosed
  • 2026-08-14: patched: Fix released in version 3.41.3

References